4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2017-9791
🔥 KEV Apache Struts Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2017 3 PoCs

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

CVE-2017-9855
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2017 1 PoC

An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can be used on any SMA inverter. Any such code, when combined with the installer account, allows changing very sensitive parameters. NOTE: the vendor reports that Grid Guard is not an authentication feature; it is only a tracing feature. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

CVE-2017-18368
🔥 KEV Software Genérico Networking
9.8
CRITICAL
EPSS
93.6%
2017 3 PoCs

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

CVE-2017-20149
Software Genérico Web Networking
9.8
CRITICAL
EPSS
6.3%
2017 2 PoCs

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.

CVE-2017-20189
Software Genérico General
9.8
CRITICAL
EPSS
3.4%
2017 4 PoCs

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.

CVE-2017-1789
Tivoli Monitoring V6 General
9.8
CRITICAL
EPSS
2.0%
2017 1 PoC

IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.

CVE-2017-7494
🔥 KEV samba General
9.8
CRITICAL
EPSS
94.2%
2017 20 PoCs

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

CVE-2017-12149
🔥 KEV jbossas Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2017 CWE-502 9 PoCs

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

CVE-2017-15944
🔥 KEV Software Genérico Networking ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2017 4 PoCs

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

CVE-2017-2891
Mongoose Web
9.8
CRITICAL
EPSS
2.9%
2017 1 PoC

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to trigger this vulnerability.

CVE-2017-2894
Mongoose General
9.8
CRITICAL
EPSS
5.1%
2017 1 PoC

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

CVE-2017-11357
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
93.7%
2017 2 PoCs

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CVE-2017-20148
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2017 1 PoC

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

CVE-2017-18362
🔥 KEV Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2017 1 PoC

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

CVE-2017-13038
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2017 1 PoC

The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:handle_mlppp().

CVE-2017-8543
🔥 KEV Microsoft Windows Windows
9.8
CRITICAL
EPSS
85.1%
2017 1 PoC

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

CVE-2004-2154
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2004 2 PoCs

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

CVE-2012-10020
FoxyPress Web Windows
9.8
CRITICAL
EPSS
68.9%
2012 CWE-434 1 PoC

The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions up to, and including, 0.4.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2012-5872
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2012 1 PoC

ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.

CVE-2012-5076
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
91.7%
2012 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.